Squiblydoo-style Rundll32/Regsvr32 Scriptlet Proxy Execution
Detects the use of rundll32.exe or regsvr32.exe to execute code via remote scripts, COM scriptlets, or JavaScript. This technique is often used in fileless malware or to bypass execution policies by loading scripts directly from a URL or local file.
CQL

